browser-agent
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building voice agents that process untrusted user audio and text through WebSocket sessions. It also documents tool-calling capabilities (e.g.,
useAgentClientTool), which represents a standard attack surface where malicious user input could attempt to influence the agent's behavior. - Ingestion points: User voice and text input are processed via
@deepgram/agentsWebSocket sessions as described inSKILL.md. - Boundary markers: The documentation does not specify explicit delimiters or instruction-guarding techniques for the data being passed to the underlying LLM.
- Capability inventory: Support for client-side tool registration (
useAgentClientTool) and session management controls (updatePrompt,sendAgentMessage) are documented inSKILL.md. - Sanitization: No specific sanitization or filtering logic is provided in the integration code snippets.
Audit Metadata